US healthcare — HIPAA Security Rule, PHI kept on-premise
For hospitals, health systems, health plans and health-tech business associates: continuous, technical evidence for the risk analysis the HIPAA Security Rule already requires, a testing cadence ready for the one HHS has proposed, and PHI and exploit evidence that never leave the hospital network.
The HIPAA Security Rule already requires an accurate and thorough assessment of the risks and vulnerabilities to electronic protected health information (45 CFR 164.308(a)(1)(ii)(A)) and a periodic technical and nontechnical evaluation (164.308(a)(8)), but it sets no testing frequency. The HHS proposal of January 6, 2025 (90 FR 898) would add one: vulnerability scans at least every six months and penetration testing at least once every 12 months. As of September 2026 it is still a proposal: no final rule has been published in the Federal Register, and the latest regulatory agenda entry targets final action for July 2027. The breach clock is already in force: individuals are notified no later than 60 calendar days after discovery.
What is on the US healthcare CISO's desk
A risk analysis that reflects real vulnerabilities
164.308(a)(1)(ii)(A) asks for an accurate and thorough assessment of risks and vulnerabilities to ePHI. A questionnaire with no technical testing is hard to defend as accurate on a network nobody has tried to break into.
The proposed six-month and 12-month floors
Proposed, not in force, and the final text may change. Building the testing program now is cheaper than retrofitting it to a compliance date, but no one should tell the board it is already required.
60 days from discovery, 500 or more to HHS
Individuals are notified within 60 calendar days of discovery (164.404). A breach affecting 500 or more individuals is reported to HHS at the same time; smaller breaches are logged and reported within 60 days after the end of the calendar year (164.408).
HHS 405(d) HICP as the practical baseline
The 2023 edition of Health Industry Cybersecurity Practices covers ten practices against five threats, ransomware and attacks on connected medical devices among them. For medium and large organizations, vulnerability management includes penetration testing and attack simulation.
How Zero Hunt fits a US health system
Technical evidence for the risk analysis
The 10-agent swarm tests what an attacker can actually reach: black box from outside the network, gray box with a standard clinical user account. Each finding records whether the vulnerability was exploited, which is what turns a risk register into an accurate one. EHR, PACS and lab systems can stay out of scope or at observe-only autonomy until you approve more, and five autonomy levels decide what waits for a human.
Detection where endpoint agents cannot run
AI traffic analysis on the appliance GPU flags exfiltration, command-and-control and mid-encryption ransomware activity, including on segments with medical devices that cannot host an agent. The signed timeline of what was seen and when feeds the breach risk assessment and the 60-day notification decision, which remains yours.
HIPAA evidence, signed and kept in-house
Findings are mapped to the Security Rule safeguards (164.308, 164.310, 164.312) and to the breach notification provisions (164.402 to 164.410), with the requirements from the 2025 proposal tracked separately and marked as proposed. Every attack attempt is an Ed25519-signed entry in a hash chain, and exported reports are ECDSA-signed.
Capability emphasis for US healthcare
- ▸PHI and exploit evidence stay on the hospital network: private AI on the appliance, no external AI API
- ▸Scan and penetration test schedules you can set to the proposed six-month and 12-month floors, or tighter
- ▸Observe-only autonomy for clinical systems and medical-device segments until you approve more
- ▸Evidence mapped once to HIPAA, NIST CSF, SOC 2 and ISO 27001 from one record store
- ▸Air-gapped mode for research or isolated clinical networks: signed updates on physical media, no internet dependency
Who buys this in US healthcare
CISO sponsoring; the HIPAA security official named under 164.308(a)(2) co-signing the risk analysis; the privacy officer using the incident timeline for breach assessments; clinical engineering agreeing the scope for medical devices; CIO and CFO authorizing because the evidence builds up all year instead of once a year, without putting PHI on another vendor platform.
Frameworks mapped for this sector, worldwide
The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:
- Global / cross-industry
- NIST Cybersecurity Framework
- SOC 2
- ISO/IEC 27001:2022
- CIS Critical Security Controls v8
- United States
- HIPAA Security Rule
Why this sector runs its AI red team on-premise, on private AI →
Go deeper on the regulations
- Definition · 5 minHuman-in-the-loop in autonomous AI security testing
Human-in-the-loop (HITL) is the design principle that an autonomous AI system acts within limits set by people and hands specific decisions — here, any action that could affect a production system — back to a human for approval before it happens.
- Playbook · 9 minAgentic AI ransomware — the containment playbook when the attacker is a model
An operational reference for containing ransomware driven end-to-end by an autonomous AI agent — when recon, lateral movement and encryption happen in seconds, with no human to interrupt.
- Definition · 5 minBlack-box vs gray-box penetration testing
Black-box and gray-box describe how much the tester knows at the start. Black-box testing starts from nothing but what the target exposes, like an outside attacker. Gray-box testing starts with partial knowledge — typically user credentials, documentation or the software's source — like an insider or an attacker who has done their homework.
Want to see this against your environment?
A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.